|
| 1 | +# MongoDB C++ Driver SSDLC Compliance Report |
| 2 | + |
| 3 | +## Release Creator |
| 4 | + |
| 5 | +- See [C/CXX Release Info](https://docs.google.com/spreadsheets/d/1yHfGmDnbA5-Qt8FX4tKWC5xk9AhzYZx1SKF4AD36ecY/edit?usp=sharing). |
| 6 | + |
| 7 | +## Process Document |
| 8 | + |
| 9 | +- Not available. <!-- CXX-3007: replace with link to public-facing document once available. --> |
| 10 | + |
| 11 | +## Tool used to track third party vulnerabilities |
| 12 | + |
| 13 | +- See [Silk](https://us1.app.silk.security/inventory/asset-group/mongodb____DedupedAssetGroup____60640b8853771efe3af5f78ea37af5d1cdd190df) (internal). |
| 14 | +- See [C++ Driver - SSDLC Reports](https://drive.google.com/drive/folders/1q9RI55trFzHlh8McALSIAbT6ugyn8zlO) for release-specific reports. |
| 15 | + |
| 16 | +## Third-Party Dependency Information |
| 17 | + |
| 18 | +- See [etc/augmented.sbom.json](https://github.com/mongodb/mongo-cxx-driver/blob/master/etc/augmented.sbom.json) within the release tarball. |
| 19 | +- See [etc/third_party_vulnerabilities.md](https://github.com/mongodb/mongo-cxx-driver/blob/master/etc/third_party_vulnerabilities.md) within the release tarball. |
| 20 | +- See [C++ Driver - SSDLC Reports](https://drive.google.com/drive/folders/1q9RI55trFzHlh8McALSIAbT6ugyn8zlO) for release-specific reports. |
| 21 | + |
| 22 | +## Static Analysis Findings |
| 23 | + |
| 24 | +- See [C++ Driver - SSDLC Reports](https://drive.google.com/drive/folders/1q9RI55trFzHlh8McALSIAbT6ugyn8zlO) for release-specific reports. |
| 25 | + |
| 26 | +## Security Testing Report |
| 27 | + |
| 28 | +- See [Driver Security Testing Summary](https://docs.google.com/document/d/1y2K_RY4GZVXpQvv4JH_35mSzFRTawNJ3mibpvSBU8H0/edit?usp=sharing) (internal). Available as needed from the MongoDB C++ Driver team. |
| 29 | + |
| 30 | +## Security Assessment Report |
| 31 | + |
| 32 | +- Not applicable to the MongoDB C++ Driver. |
| 33 | + |
| 34 | +## Signature Information |
| 35 | + |
| 36 | +- The source tarball for each release is accompanied by a detached GPG digital signature which may be verified against the `cpp-driver` public key available at https://pgp.mongodb.com/. |
| 37 | + |
| 38 | +## Known Vulnerabilities |
| 39 | + |
| 40 | +- Any vulnerabilities that may be shown in the links referenced above have been reviewed and accepted by the appropriate approvers. For detailed information, see [C++ Driver - SSDLC Reports](https://drive.google.com/drive/folders/1q9RI55trFzHlh8McALSIAbT6ugyn8zlO) for release-specific reports. |
0 commit comments